An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
{
"cwe_ids": [
"CWE-287",
"CWE-863"
],
"nvd_published_at": "2023-10-25T18:17:32Z",
"github_reviewed": true,
"severity": "HIGH",
"github_reviewed_at": "2023-10-27T19:49:44Z"
}